Skip to content
Distr
Book DemoStart free trialLogin
← Back to Glossary

Security Update vs Functionality Update: The CRA Distinction

Why the Cyber Resilience Act requires security updates to be delivered separately from feature updates, and what that means for release engineering.

Under the Cyber Resilience Act, a security update is an update that addresses vulnerabilities, and manufacturers must deliver it separately from functionality updates where technically feasible (Annex I, Part II, point 2). The distinction matters because it protects the user’s choice: a customer running a supported version must be able to apply a security patch without being forced to adopt new features, behavior changes, or a major version upgrade at the same time. In practice this means maintaining patch releases for supported version lines rather than shipping fixes only in the newest feature release.

The CRA adds further conditions on the security side: security updates must be disseminated without delay and, unless agreed otherwise with a business user for a tailor-made product, free of charge, accompanied by advisory messages with the relevant information for users (Annex I, Part II, point 8), and each security update issued during the support period must remain available for at least 10 years (Article 13(9)). Functionality updates carry no such obligations.

How this works operationally for self-hosted and air-gapped customers is covered in our guide on delivering security updates under the CRA.

Frequently Asked Questions

Does the CRA require free security updates?

Yes. Security updates must be disseminated without delay and, unless agreed otherwise with a business user for a tailor-made product, free of charge, accompanied by advisory messages (Annex I, Part II, point 8).

How long must security updates stay available?

Each security update issued during the support period must remain available for at least 10 years after it was issued, or for the remainder of the support period, whichever is longer (Article 13(9)).

Turn self-hosted into a repeatable sales motion

From your first on-prem POC to dozens of enterprise customers, the Distr platform gives you the tooling to deploy, update and manage self-hosted customers, backed by a team that supports you hands-on with the deployment knowledge and implementation help.

Proof from teams shipping self-hosted software

GovCloud deployments without extra overhead

"Distr gives us a clean way to deploy and update our software in GovCloud without breaking security or adding operational overhead."

Corbin Klett

Corbin Klett

Co-Founder, Artifact

Manual operations become one-click workflows

"Our main goal is to simplify the daily operations. No more manual installations, updates, or rollbacks — everything can now be handled with a single click with Distr."

Jefferson Rodrigues

Jefferson Rodrigues

Co-Founder & CTO, Lerian

Read case study

Updates that took days now take minutes

"Distr eliminated nearly all deployment headaches. Updates that used to take days now take minutes."

Ansh Gupta

Ansh Gupta

CTO, Sophris.ai

Read case study

One place for every self-hosted customer

"Having a dedicated space for all our self-hosted customers that can manage authenticated registry access is great."

Derek Reynolds

Derek Reynolds

Product Engineer, Basedash

Read case study

From guided setup to scalable delivery

"We went from hands-on Docker setup calls to an install flow that can be running in minutes."

Daniel Kasen

Daniel Kasen

Chief Engineer for Customer Success, Ozgar AI

Read case study

Self-hosted without the engineering tax

"Weave has a fully self-hosted offering. It's a huge unlock for us, but we almost didn't build it. Distr made such a huge difference in getting us there."

Andrew Churchill

Andrew Churchill

Co-Founder & CTO, Weave

Read case study